VulnSea

LMCache vulnerabilities

CVEs whose affected-version data names the LMCache package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-107207High· 7.2
today

LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts

LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts. Attackers can add entries v…

▾ TwilightLMCache · LMCachevia NVD
CVE-2026-107206Critical· 9.4PoC
today

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can …

▾ AbyssalLMCache · LMCachevia NVD
CVE-2026-107205High· 8.6
today

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can…

▾ TwilightLMCache · LMCachevia NVD
CVE-2026-107204Critical· 9.8PoC
today

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the inj…

▾ AbyssalLMCache · LMCachevia NVD
CVE-2026-105192Critical· 9.8
today

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapp…

▾ MidnightLMCache · lmcacheEPSS 0.67%via NVD
CVE-2026-10813Low· 3.6
4mo ago

LMCache: 16-bit multimodal hash collision can poison KV cache entries

LMCache: 16-bit multimodal hash collision can poison KV cache entries

▾ Sunlitlmcache · lmcacheEPSS 0.07%via OSV
LMCache vulnerabilities (CVEs) · VulnSea